CVE-2016-9061: High severity firefox vulnerability
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-5296
- CVE-2016-5292
- CVE-2016-5293
- CVE-2016-5294
- CVE-2016-5297
- CVE-2016-9064
- CVE-2016-9065
- CVE-2016-9066
- CVE-2016-9067
- CVE-2016-9068
- CVE-2016-9072
- CVE-2016-9075
- CVE-2016-9077
- CVE-2016-5291
- CVE-2016-5295
- CVE-2016-5298
- CVE-2016-5299
- CVE-2016-9061
- CVE-2016-9062
- CVE-2016-9070
- CVE-2016-9073
- CVE-2016-9074
- CVE-2016-9076
- CVE-2016-9063
- CVE-2016-9071
- CVE-2016-5289
- CVE-2016-5290
Frequently Asked Questions
What is the severity of CVE-2016-9061?
The severity of CVE-2016-9061 is high, with a CVSS score of 7.5.
Which software is affected by CVE-2016-9061?
The software affected by CVE-2016-9061 is Mozilla Firefox for Android, versions up to and excluding 50.0.
What is the impact of CVE-2016-9061?
CVE-2016-9061 allows a previously installed malicious Android app to access API keys meant for Firefox, potentially compromising user data.
How can I fix CVE-2016-9061?
To fix CVE-2016-9061, update Mozilla Firefox for Android to a version higher than 50.0.
Are other versions and operating systems affected by CVE-2016-9061?
No, other versions and operating systems are unaffected by CVE-2016-9061.